Back to overview

CVE-2025-47916

CRITICAL Exploitation: PoC
10.0
CVSS 3.1
Description
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within the themeeditor controller (file: /applications/core/modules/front/system/themeeditor.php), where a protected method named customCss can be invoked by unauthenticated users. This method passes the value of the content parameter to the Theme::makeProcessFunction() method; hence it is evaluated by the template engine. Accordingly, this can be exploited by unauthenticated attackers to inject and execute arbitrary PHP code by providing crafted template strings.

Metadata

CVE ID
CVE-2025-47916
State
PUBLISHED
Assigner
mitre
Reserved
2025-05-14 00:00 UTC
Published
2025-05-16 00:00 UTC
Last updated
2025-05-17 05:03 UTC
Primary CWE
CWE-1336
CWE-1336 Improper Neutralization of Special Elements Used in…
Vendor / Product
invisioncommunity / Invision Power Board
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
invisioncommunity Invision Power Board 5.0.0 < 5.0.7
Weakness (CWE)
CWESourceDescription
CWE-1336 cna CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview